• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

通过动态访问控制策略转换实现分布式临床数据共享。

Distributed clinical data sharing via dynamic access-control policy transformation.

作者信息

Rezaeibagha Fatemeh, Mu Yi

机构信息

Centre for Computer and Information Security Research, School of Computing and Information Technology, University of Wollongong, NSW, Australia.

Centre for Computer and Information Security Research, School of Computing and Information Technology, University of Wollongong, NSW, Australia.

出版信息

Int J Med Inform. 2016 May;89:25-31. doi: 10.1016/j.ijmedinf.2016.02.002. Epub 2016 Feb 12.

DOI:10.1016/j.ijmedinf.2016.02.002
PMID:26980356
Abstract

BACKGROUND

Data sharing in electronic health record (EHR) systems is important for improving the quality of healthcare delivery. Data sharing, however, has raised some security and privacy concerns because healthcare data could be potentially accessible by a variety of users, which could lead to privacy exposure of patients. Without addressing this issue, large-scale adoption and sharing of EHR data are impractical. The traditional solution to the problem is via encryption. Although encryption can be applied to access control, it is not applicable for complex EHR systems that require multiple domains (e.g. public and private clouds) with various access requirements.

OBJECTIVES

This study was carried out to address the security and privacy issues of EHR data sharing with our novel access-control mechanism, which captures the scenario of the hybrid clouds and need of access-control policy transformation, to provide secure and privacy-preserving data sharing among different healthcare enterprises.

METHODS

We introduce an access-control mechanism with some cryptographic building blocks and present a novel approach for secure EHR data sharing and access-control policy transformation in EHR systems for hybrid clouds.

RESULTS

We propose a useful data sharing system for healthcare providers to handle various EHR users who have various access privileges in different cloud environments. A systematic study has been conducted on data sharing in EHR systems to provide a solution to the security and privacy issues.

CONCLUSIONS

In conclusion, we introduce an access-control method for privacy protection of EHRs and EHR policy transformation that allows an EHR access-control policy to be transformed from a private cloud to a public cloud. This method has never been studied previously in the literature. Furthermore, we provide a protocol to demonstrate policy transformation as an application scenario.

摘要

背景

电子健康记录(EHR)系统中的数据共享对于提高医疗服务质量至关重要。然而,数据共享引发了一些安全和隐私问题,因为医疗数据可能会被各类用户访问,这可能导致患者隐私泄露。如果不解决这个问题,大规模采用和共享EHR数据是不切实际的。传统的解决方法是通过加密。虽然加密可用于访问控制,但它不适用于需要多个具有不同访问要求的域(如公共云和私有云)的复杂EHR系统。

目的

本研究旨在通过我们新颖的访问控制机制解决EHR数据共享的安全和隐私问题,该机制捕捉了混合云场景以及访问控制策略转换的需求,以在不同医疗企业之间提供安全且保护隐私的数据共享。

方法

我们引入一种带有一些加密构建块的访问控制机制,并提出一种在混合云的EHR系统中进行安全EHR数据共享和访问控制策略转换的新颖方法。

结果

我们为医疗服务提供者提出了一个有用的数据共享系统,以处理在不同云环境中具有不同访问权限的各类EHR用户。已对EHR系统中的数据共享进行了系统研究,以提供安全和隐私问题的解决方案。

结论

总之,我们引入了一种用于EHR隐私保护和EHR策略转换的访问控制方法,该方法允许将EHR访问控制策略从私有云转换到公共云。该方法此前在文献中从未被研究过。此外,我们提供了一个协议来演示作为应用场景的策略转换。

相似文献

1
Distributed clinical data sharing via dynamic access-control policy transformation.通过动态访问控制策略转换实现分布式临床数据共享。
Int J Med Inform. 2016 May;89:25-31. doi: 10.1016/j.ijmedinf.2016.02.002. Epub 2016 Feb 12.
2
Efficient Privacy-Preserving Access Control Scheme in Electronic Health Records System.电子健康记录系统中的高效隐私保护访问控制方案。
Sensors (Basel). 2018 Oct 18;18(10):3520. doi: 10.3390/s18103520.
3
A secure EHR system based on hybrid clouds.基于混合云的安全电子健康记录系统。
J Med Syst. 2012 Oct;36(5):3375-84. doi: 10.1007/s10916-012-9830-6. Epub 2012 Feb 21.
4
Secured and Privacy-Preserving Multi-Authority Access Control System for Cloud-Based Healthcare Data Sharing.基于云的医疗保健数据共享的安全和隐私保护多授权访问控制系统。
Sensors (Basel). 2023 Feb 27;23(5):2617. doi: 10.3390/s23052617.
5
A systematic literature review on security and privacy of electronic health record systems: technical perspectives.电子健康记录系统的安全性与隐私性:技术视角的系统文献综述
Health Inf Manag. 2015;44(3):23-38. doi: 10.1177/183335831504400304.
6
Patient and public views about the security and privacy of Electronic Health Records (EHRs) in the UK: results from a mixed methods study.英国患者及公众对电子健康记录(EHRs)安全性和隐私性的看法:一项混合方法研究的结果
BMC Med Inform Decis Mak. 2015 Oct 14;15:86. doi: 10.1186/s12911-015-0202-2.
7
Secure Dynamic access control scheme of PHR in cloud computing.云计算中 PHR 的安全动态访问控制方案。
J Med Syst. 2012 Dec;36(6):4005-20. doi: 10.1007/s10916-012-9873-8. Epub 2012 Aug 28.
8
Cloud-assisted mobile-access of health data with privacy and auditability.云辅助的移动健康数据访问,具有隐私性和可审计性。
IEEE J Biomed Health Inform. 2014 Mar;18(2):419-29. doi: 10.1109/JBHI.2013.2294932.
9
Public and physician's expectations and ethical concerns about electronic health record: Benefits outweigh risks except for information security.公众和医生对电子健康记录的期望和伦理关注:除了信息安全外,好处大于风险。
Int J Med Inform. 2018 Feb;110:98-107. doi: 10.1016/j.ijmedinf.2017.12.004. Epub 2017 Dec 12.
10
Meeting EHR security requirements: SeAAS approach.满足电子健康记录(EHR)安全要求:SeAAS方法。
Stud Health Technol Inform. 2010;155:85-91.

引用本文的文献

1
GPT, ontology, and CAABAC: A tripartite personalized access control model anchored by compliance, context and attribute.GPT、本体论与CAABAC:一种以合规性、上下文和属性为支撑的三方个性化访问控制模型。
PLoS One. 2025 Jan 6;20(1):e0310553. doi: 10.1371/journal.pone.0310553. eCollection 2025.
2
On the Design of Secured and Reliable Dynamic Access Control Scheme of Patient E-Healthcare Records in Cloud Environment.云环境中患者电子医疗记录的安全可靠动态访问控制方案设计。
Comput Intell Neurosci. 2022 Aug 18;2022:3804553. doi: 10.1155/2022/3804553. eCollection 2022.
3
A Comprehensive Survey on Security and Privacy for Electronic Health Data.
电子健康数据的安全与隐私问题综述
Int J Environ Res Public Health. 2021 Sep 14;18(18):9668. doi: 10.3390/ijerph18189668.
4
ReportFlow: an application for EEG visualization and reporting using cloud platform.报告流程:一款使用云平台进行脑电图可视化和报告的应用程序。
BMC Med Inform Decis Mak. 2021 Jan 6;21(1):7. doi: 10.1186/s12911-020-01369-7.